Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
MineAdmin JWT Token refresh data authenticity
Vulnerability Description
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
对数据真实性的验证不充分
Vulnerability Title
MineAdmin 数据伪造问题漏洞
Vulnerability Description
MineAdmin是MineAdmin开源的一个权限管理系统。 MineAdmin 1.x版本和2.x版本存在数据伪造问题漏洞,该漏洞源于对数据真实性验证不足。
CVSS Information
N/A
Vulnerability Type
N/A